Security Certification in Payment Card Industry: Testbeds, Measurements, and Recommendations

Security Certification in Payment Card Industry: Testbeds, Measurements, and Recommendations
复制标题

DOI:
10.1145/3319535.3363195
复制
发表时间:
2019-11
期刊:
Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Sazzadur Rahaman;Gang Wang;D. Yao
Sazzadur Rahaman;Gang Wang;D. Yao
中科院分区:
其他
文献类型:
--
作者:
Sazzadur Rahaman;Gang Wang;D. Yao

文献摘要

被引文献

相似文献

庞大的支付卡行业(PCI)涉及各种实体,如商家、发卡银行、收单行和卡品牌。确保处理支付卡信息的所有实体的安全是一项具有挑战性的任务。PCI安全标准委员会要求所有实体遵守PCI数据安全标准(DSS),该标准规定了一系列安全要求。然而,关于PCIDSS在实践中的执行情况却知之甚少。本文采用计量方法对电子商务网站的PCIDSS认证过程进行了系统评价。我们开发了一个电子商务Web应用测试平台BuggyCart,它可以灵活地添加或删除35个与PCIDSS相关的漏洞。然后,我们使用测试床来检查PCI扫描仪的能力和局限性以及认证过程的严格性。我们发现,安全标准与现实世界的执行之间存在着令人震惊的差距。我们测试的6台PCI扫描仪中没有一台完全符合PCI扫描指南,会向仍然存在重大漏洞的商家颁发证书。为了进一步检查现实世界电子商务网站的合规状况,我们构建了一个新的轻量级扫描工具PciCheckerLite,并对不同业务领域的1,203个电子商务网站进行了扫描。结果证实,86%的网站至少有一次违反PCIDSS的行为,本应因不合规而取消资格。我们的深入精度分析还表明,PciCheckerLite的输出比w3af更精确。我们联系了PCI安全理事会,分享了我们的研究成果,以改进实践中的执法。
The massive payment card industry (PCI) involves various entities such as merchants, issuer banks, acquirer banks, and card brands. Ensuring security for all entities that process payment card information is a challenging task. The PCI Security Standards Council requires all entities to be compliant with the PCI Data Security Standard (DSS), which specifies a series of security requirements. However, little is known regarding how well PCI DSS is enforced in practice. In this paper, we take a measurement approach to systematically evaluate the PCI DSS certification process for e-commerce websites. We develop an e-commerce web application testbed, BuggyCart, which can flexibly add or remove 35 PCI DSS related vulnerabilities. Then we use the testbed to examine the capability and limitations of PCI scanners and the rigor of the certification process. We find that there is an alarming gap between the security standard and its real-world enforcement. None of the 6 PCI scanners we tested are fully compliant with the PCI scanning guidelines, issuing certificates to merchants that still have major vulnerabilities. To further examine the compliance status of real-world e-commerce websites, we build a new lightweight scanning tool named PciCheckerLite and scan 1,203 e-commerce websites across various business sectors. The results confirm that 86% of the websites have at least one PCI DSS violation that should have disqualified them as non-compliant. Our in-depth accuracy analysis also shows that PciCheckerLite's output is more precise than w3af. We reached out to the PCI Security Council to share our research results to improve the enforcement in practice.